Executive brief
A vulnerability in the SoliClub application allows unauthorized individuals to access private personal information. SoliClub is a platform used for campus and corporate services such as payments and access control. An exploit could lead to the large-scale exposure of sensitive user data, potentially resulting in privacy violations and identity theft risks for affected individuals.
Technical details
An Information Exposure vulnerability (CWE-359) exists in Utarit Informatics Services Inc. SoliClub versions 5.2.4 through 5.3.6. The flaw resides in the application's query system, which fails to properly restrict access to sensitive data. A remote, unauthenticated attacker can exploit this over the network to retrieve private personal information without authorization. The vulnerability was addressed in version 5.3.7.
Affected products
- Utarit Informatics Services Inc. SoliClub from 5.2.4 before 5.3.7
Timeline
- 2025-12-18: disclosed
- 2025-12-18: advisory